Documentation
¶
Index ¶
- Constants
- func StartCertificateRetentionWorker(ctx context.Context, pool *pgxpool.Pool)
- type BindingVerifier
- func (v *BindingVerifier) ResolveRuntimeDeviceIdentity(ctx context.Context, credentialID uuid.UUID) (coreruntime.RuntimeDeviceIdentity, error)
- func (v *BindingVerifier) ResolveTokenOnlyRuntimeDeviceIdentity(ctx context.Context, credentialID uuid.UUID, nodeID uuid.UUID) (coreruntime.RuntimeDeviceIdentity, error)
- func (v *BindingVerifier) VerifyRuntimePrincipalBinding(ctx context.Context, credentialID uuid.UUID, ...) error
- type ClientCertificate
- type CredentialRequest
- type CredentialResponse
- type CredentialService
- type Manager
- type RuntimeTokenValidator
Constants ¶
View Source
const (
ClientCertificateLifetime = 24 * time.Hour
)
Variables ¶
This section is empty.
Functions ¶
func StartCertificateRetentionWorker ¶
StartCertificateRetentionWorker prunes only certificate audit inventory. It is intentionally independent from the optional automatic PKI manager so deployments that disable mTLS still converge historical certificate rows.
Types ¶
type BindingVerifier ¶
type BindingVerifier struct {
// contains filtered or unexported fields
}
func NewBindingVerifier ¶
func NewBindingVerifier(pool *pgxpool.Pool) *BindingVerifier
func (*BindingVerifier) ResolveRuntimeDeviceIdentity ¶
func (v *BindingVerifier) ResolveRuntimeDeviceIdentity(ctx context.Context, credentialID uuid.UUID) (coreruntime.RuntimeDeviceIdentity, error)
func (*BindingVerifier) ResolveTokenOnlyRuntimeDeviceIdentity ¶
func (v *BindingVerifier) ResolveTokenOnlyRuntimeDeviceIdentity( ctx context.Context, credentialID uuid.UUID, nodeID uuid.UUID, ) (coreruntime.RuntimeDeviceIdentity, error)
func (*BindingVerifier) VerifyRuntimePrincipalBinding ¶
func (v *BindingVerifier) VerifyRuntimePrincipalBinding( ctx context.Context, credentialID uuid.UUID, device coreruntime.RuntimeDeviceIdentity, ) error
type ClientCertificate ¶
type CredentialRequest ¶
type CredentialRequest struct {
NodeID string `json:"node_id"`
DisplayName string `json:"display_name"`
NodeVersion string `json:"node_version"`
ProtocolVersion int32 `json:"protocol_version"`
RuntimeContractID string `json:"runtime_contract_id"`
RuntimeContractDigest string `json:"runtime_contract_digest"`
Features []string `json:"features"`
Capacity int32 `json:"capacity"`
CSRPEM string `json:"csr_pem"`
}
type CredentialResponse ¶
type CredentialResponse struct {
NodeID string `json:"node_id"`
AgentID string `json:"agent_id"`
CertificatePEM string `json:"certificate_pem"`
CertificateChainPEM string `json:"certificate_chain_pem"`
TrustBundlePEM string `json:"trust_bundle_pem"`
CertificateSerial string `json:"certificate_serial"`
PublicKeyThumbprint string `json:"public_key_thumbprint"`
NotBefore time.Time `json:"not_before"`
NotAfter time.Time `json:"not_after"`
RenewAfter time.Time `json:"renew_after"`
CertificateLifetimeHr int `json:"certificate_lifetime_hours"`
}
type CredentialService ¶
type CredentialService struct {
// contains filtered or unexported fields
}
func NewCredentialService ¶
func NewCredentialService(pool *pgxpool.Pool, authority *Manager, tokens RuntimeTokenValidator) *CredentialService
func (*CredentialService) Register ¶
func (s *CredentialService) Register(api *echo.Group)
func (*CredentialService) RegisterTrustBundle ¶
func (s *CredentialService) RegisterTrustBundle(e *echo.Echo)
type Manager ¶
type Manager struct {
// contains filtered or unexported fields
}
Manager owns the default self-managed Runtime trust hierarchy. CA private keys are encrypted before persistence and are shared through PostgreSQL, so HA replicas do not require operators to distribute CA files.
func NewManager ¶
func (*Manager) IssueClientCertificate ¶
func (m *Manager) IssueClientCertificate(csr *x509.CertificateRequest, nodeID uuid.UUID) (ClientCertificate, error)
func (*Manager) TrustBundlePEM ¶
type RuntimeTokenValidator ¶
Click to show internal directories.
Click to hide internal directories.